CVE-2026-34473
Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181A, and H196Q. A denial-of-service condition can be triggered against the router's web interface by sending an oversized application/x-www-form-urlencoded POST body. After triggering, the management interface may become unresponsive until the device is rebooted. This may affect any firmware version prior to 2022 (reporter observation). The supplier stated that devices are not vulnerable since 2021-03-23; operator firmware may vary.
Published:May 6, 2026
Last Modified:May 30, 2026
EPS:May 6, 2026
EPSS Score:0.01634
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Zte
Product
H167A
Zte
H167A
Vendor
Zte
Product
H168N
Zte
H168N
Vendor
Zte
Product
H181A
Zte
H181A
Vendor
Zte
Product
H196A
Zte
H196A
Vendor
Zte
Product
H196Q
Zte
H196Q
Vendor
Zte
Product
H198A
Zte
H198A
Vendor
Zte
Product
H199A
Zte
H199A
Vendor
Zte
Product
H208N
Zte
H208N
Vendor
Zte
Product
H267A
Zte
H267A
Vendor
Zte
Product
H267N
Zte
H267N
Vendor
Zte
Product
H268A
Zte
H268A
Vendor
Zte
Product
H268N
Zte
H268N
Vendor
Zte
Product
H288A
Zte
H288A
Vendor
Zte
Product
H367N
Zte
H367N
Vendor
Zte
Product
H369A
Zte
H369A
Vendor
Zte
Product
H388X
Zte
H388X
Vendor
Zte
Product
H8102E
Zte
H8102E
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
